Ray Security & Risk Analysis

wordpress.org/plugins/spatie-ray

Easily debug WordPress sites using Ray.

500 active installs v1.7.10 PHP 8.0+ WP 5.5+ Updated Dec 10, 2025
debugdebuggingdeveloperdevelopment
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ray Safe to Use in 2026?

Generally Safe

Score 100/100

Ray has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The spatie-ray plugin v1.7.10 exhibits a strong security posture based on the provided static analysis. There are no identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that are directly accessible. Furthermore, the code demonstrates excellent security practices by avoiding dangerous functions, not performing raw SQL queries, and properly escaping all outputs. The absence of file operations, external HTTP requests, and a clear lack of critical or high-severity issues in taint analysis further solidify this positive assessment. The plugin also has no recorded vulnerability history, indicating a consistent focus on security by its developers.

While the plugin's core functionality appears very secure, the complete lack of identified entry points is unusual and could potentially be an incomplete picture of the attack surface. The absence of nonce and capability checks, while not a direct concern given the zero entry points, would be a significant weakness if any were present. Overall, the plugin is exceptionally well-coded from a security perspective with no immediate threats detected, but a complete understanding of its integration points would be beneficial.

Vulnerabilities
None known

Ray Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Ray Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Ray Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionwp_error_addedsrc\Loggers\ErrorLogger.php:16
actionallsrc\Loggers\HookLogger.php:18
actionphpmailer_initsrc\Loggers\MailLogger.php:20
filterlog_query_custom_datasrc\Loggers\QueryLogger.php:22
Maintenance & Trust

Ray Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedDec 10, 2025
PHP min version8.0
Downloads35K

Community Trust

Rating100/100
Number of ratings10
Active installs500
Developer Profile

Ray Developer Profile

freekmurze

2 plugins · 520 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ray

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Ray